Skip to content
SECURITY · EXPLAINER

Your Encrypted Data Could Be Stolen Now—and Read Years Later

The quantum security problem is not just when a powerful computer arrives. It is how long the information you send today needs to stay secret.

Sources checked Published
My reading list
Desks, monitors and wall displays in a network operations center.
A network operations center photographed in 2006. Ordinary infrastructure context, not evidence of an intrusion or a quantum attack. Cropped/resized; no generative edits.Photo: Network Operations Center (NOC-IUPUI) · Alan Levine · CC BY 2.0

A stolen encrypted file does not have to be readable today to become a problem. An attacker can keep it and hope that future technology unlocks it. That is the idea behind “harvest now, decrypt later,” and it explains why the quantum security debate is not only about the date a powerful computer might arrive.[1]

In a July 2026 interview, NIST emphasized the mismatch between those timelines. Medical records, business secrets and government information can remain sensitive for years. Moving systems to new cryptography also takes time. Waiting for a cryptographically relevant quantum computer could leave yesterday’s captured data exposed to tomorrow’s attack.[1]

A fiber-splicing truck, road cones and cable beside an open utility access point.
A mobile fiber-splicing lab accessing underground cable. Network-infrastructure context, not an interception scene or quantum-security installation. Cropped/resized; no generative edits.Photo: Fiber Splice Lab · Dhaluza at English Wikipedia · CC BY 3.0

The threat is specific, not magical. A sufficiently capable quantum computer could attack widely used public-key methods that help establish secure connections. It would not automatically read every password, decrypt every protected file or defeat every form of encryption. Exposure depends on what was captured and how it was protected.[1][2]

Post-quantum cryptography changes the mathematical protection; it does not require everyone to buy a quantum device. NIST finalized its first three standards in 2024. For an individual, keeping software updated matters. For an organization, identifying where vulnerable cryptography is used is a more useful starting point than guessing a dramatic “Q-day.”[1][2]

Overhead view of IBM Quantum System Two at Ikerbasque, with visitors beneath the installation.
IBM Quantum System Two hardware. Its appearance does not imply it can break deployed encryption; the article concerns a possible future threat. Cropped/resized; no generative edits.Photo: IBM Quantum System Two at Ikerbasque · Íñigo Sierra / Irekia–Eusko Jaurlaritza · CC BY 3.0 ES

There is no verified countdown in this story, and no claim that current quantum processors can routinely break today’s deployed public-key security. The practical question is simpler: will this information still matter when stronger attacks become possible? A secret’s shelf life can be longer than the technology protecting it.[1][2]

READ NEXT

Continue exploring

All Security stories
  1. Related reading

    IETF Publishes Hybrid ML-KEM Key Agreement for TLS 1.3

    RFC 10024 specifies three combinations of ML-KEM and elliptic-curve key agreement at Proposed Standard maturity.

    Source date
  2. Related reading

    IETF Publishes Post-Quantum Algorithms for OpenPGP

    RFC 9980 adds composite encryption and signatures, plus standalone hash-based signatures, to the OpenPGP protocol.

    Source date
THE QUANTUM BRIEFING

A clearer signal.
Straight to your inbox.

A little perspective on a fast-moving field.

Read a briefing preview →

Selected quantum coverage in a weekly briefing. Read the preview or register your interest.